From e5e23407c1c1dc4998a6b3bf5ac8bc8b60376351 Mon Sep 17 00:00:00 2001 From: Ori Nimron Date: Fri, 20 Sep 2019 09:35:47 +0200 Subject: [PATCH] ax25: enforce CAP_NET_RAW for raw sockets commit 0614e2b73768b502fc32a75349823356d98aae2c upstream. When creating a raw AF_AX25 socket, CAP_NET_RAW needs to be checked first. Signed-off-by: Ori Nimron Signed-off-by: Greg Kroah-Hartman Signed-off-by: David S. Miller Signed-off-by: Ben Hutchings CVE-2019-17052 Signed-off-by: Kevin F. Haggerty Change-Id: I4b781c10113621f943df41bb5ed7caf2219ae36f --- net/ax25/af_ax25.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/net/ax25/af_ax25.c b/net/ax25/af_ax25.c index f59c8af13e5..63c83ce3d5b 100644 --- a/net/ax25/af_ax25.c +++ b/net/ax25/af_ax25.c @@ -857,6 +857,8 @@ static int ax25_create(struct net *net, struct socket *sock, int protocol, break; case SOCK_RAW: + if (!capable(CAP_NET_RAW)) + return -EPERM; break; default: return -ESOCKTNOSUPPORT;